Req #62363 [Opn->Nab]: Lack of warning about anon. bind

From: Date: Mon, 09 Jan 2017 06:45:59 +0000
Subject: Req #62363 [Opn->Nab]: Lack of warning about anon. bind
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206431@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62363&edit=1

 ID:                 62363
 Updated by:         heiglandreas@php.net
 Reported by:        gewalopdrbat at gmail dot com
 Summary:            Lack of warning about anon. bind
-Status:             Open
+Status:             Not a bug
 Type:               Feature/Change Request
 Package:            LDAP related
 Operating System:   Windows 7, Ubuntu 12.04
 PHP Version:        5.4.4
 Block user comment: N
 Private report:     N

 New Comment:

This issue is targeting a deprecated version of PHP. And as ldap_bind is per RFC 2251 doing an
anonymous bind when the password is left empty that's not a behaviour that should trigger a
warning as it's the defined behaviour. And as it results in an anonymous bind it's not a
security issue. 

You are right in that this behaviour should be reflected in the docs though!

So I'm closing this issue here now.


Previous Comments:
------------------------------------------------------------------------
[2012-06-19 07:11:44] gewalopdrbat at gmail dot com

Description:
------------
Most of the cases where a security concern or a possibility unexpected behavior are happily
mentioned in the PHP documentation as WARNINGS or NOTES.
This case is very critical because many times the ldap_bind() function is used as in the Case 1 (see
test script).
According the https://tools.ietf.org/html/rfc4513#section-5.1.2
, Clients MUST check for empty passwords to avoid successful bind when the username is valid
(I've also tested the username '*', and it produced a successful bind).
It would be very nice to change the behavior of ldap_bind() and add a parameter to explicitly allow
anonymous binding or at least mention the Case 2 in the examples (see test script).

Test script:
---------------
#Case 1 Code
if (ldap_bind($ds, $rdn, $password)){
       //reveal secret stuff
}

#Case 2 Code
if (!empty($password) || $password != null) {
       if (ldap_bind($ds, escapeLDAP($rdn, 'dn'), $password)) {
            //reveal secret stuff
}



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=62363&edit=1


Thread (1 message)

  • heiglandreas@php.net
  • Unknown Message
    • heiglandreas@php.net
« previous php.bugs (#206431) next »